Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spip | Spip | <= 3.1.2 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/10/05/17Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/10/06/6Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/10/12/6Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93451
- https://core.spip.net/projects/spip/repository/revisions/23201Issue TrackingPatchVendor Advisory
- https://core.spip.net/projects/spip/repository/revisions/23202Issue TrackingPatchVendor Advisory
- https://core.spip.net/projects/spip/repository/revisions/23203Issue TrackingPatchVendor Advisory
- https://sysdream.com/news/lab/2016-10-19-spip-3-1-2-exec-code-cross-site-request
- http://www.openwall.com/lists/oss-security/2016/10/05/17Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/10/06/6Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/10/12/6Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93451
- https://core.spip.net/projects/spip/repository/revisions/23201Issue TrackingPatchVendor Advisory
- https://core.spip.net/projects/spip/repository/revisions/23202Issue TrackingPatchVendor Advisory
- https://core.spip.net/projects/spip/repository/revisions/23203Issue TrackingPatchVendor Advisory
FAQ
What is CVE-2016-7980?
CVE-2016-7980 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execut...
How severe is CVE-2016-7980?
CVE-2016-7980 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-7980?
Check the references section above for vendor advisories and patch information. Affected products include: Spip Spip.